PT-2026-98850 · Kitty · Kitty

·

CVE-2026-80431

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions kitty versions 0.40.0 through 0.48.x
Description An out-of-bounds write exists in the natural width branch of the text sizing protocol. The screen handle multicell command() function in kitty/screen.c appends each codepoint of a grapheme cluster using lc.chars[lc.count++] = ch without performing a capacity check. Because lc is declared as a four-element char type array via the RAII ListOfChars macro, an OSC 66 escape code containing a grapheme cluster longer than four codepoints writes beyond the buffer. If the cluster is preceded by a sequence causing an intermediate flush, the buffer is migrated to the heap by ensure space for chars(), and the write occurs past the heap allocation. This leads to the termination of the kitty process, including all associated windows, tabs, and child processes.
Recommendations Update to version 0.49.0 or later.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80431

Affected Products

Kitty